Google routes return 500 on a missing OAuth state or a missing or partial JSON body #56
Labels
No labels
bug
chore
data
feature
frontend
good first issue
intermediate
needs/docs
needs/research
needs/upstream
type/bug
type/external
type/feature
type/refactor
urgency
high
urgency
immediate
urgency
low
urgency
medium
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
ScottyLabs/cal#56
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What's wrong
GET /api/google/oauth/callbackreadssession["state"](L78) with no guard. Hitting the callback without going through/api/google/authorizefirst (expired cookie, second tab, bookmark) raises KeyError, so 500.POST /api/google/calendar/events/add(L134-172): no body gives 500 (Flask's 415 is swallowed byexcept Exception).data["start"],data["end"],data["title"]anddata["local_event_id"]are never validated, andlocal_event_idis read only afteradd_event()has already created the event in Google, so a body without it leaves an orphan event in the user's Google Calendar and still returns 500.POST /api/google/calendar/events/bulk(L125-131):request.get_json().get(...)raises AttributeError for anullbody, so 500.The DELETE route takes no body and is fine.
How to reproduce
In tests,
mocker.patch("app.api.google.fetch_user_credentials", return_value={"token": "t"}), and also mockadd_eventand give the user acalendar_id.Expected
Where to look
api/app/api/google.py:oauth2callback()L75-87,bulk_events()L125-131,add_event_route()L134-172.api/app/utils/date.pyconvert_to_iso8601()(raises ValueError on any other date format).2c5f2e9.Done when
api/tests/api/test_google_validation.py